ISO/IEC 27005:2008 PDF
Information technology — Security techniques — Information security risk management
Information technology — Security techniques — Information security risk management
- Document status:
- Withdrawn
- Format:
- Electronic (PDF)
- Number of pages:
- 55
- Publication date:
- June 4, 2008
- Edition:
- ISO/IEC IS 27005 edition 1 version 1
- ICS:
- 03.100.70
ISO/IEC 27005:2008 provides guidelines for information security risk management. It supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach. Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is important for a complete understanding of ISO/IEC 27005:2008. ISO/IEC 27005:2008 is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that could compromise the organization's information security.
Technical details
- Technical committee
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27005:2008


